Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-05-12 CVE-2022-29987 SQL Injection vulnerability in Online Sports Complex Booking System Project Online Sports Complex Booking System 1.0
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=user/manage_user&id=.
network
low complexity
online-sports-complex-booking-system-project CWE-89
critical
9.8
2022-05-12 CVE-2022-29988 SQL Injection vulnerability in Online Sports Complex Booking System Project Online Sports Complex Booking System 1.0
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete.
network
low complexity
online-sports-complex-booking-system-project CWE-89
critical
9.8
2022-05-12 CVE-2022-29989 SQL Injection vulnerability in Online Sports Complex Booking System Project Online Sports Complex Booking System 1.0
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_booking.
network
low complexity
online-sports-complex-booking-system-project CWE-89
critical
9.8
2022-05-12 CVE-2022-29990 SQL Injection vulnerability in Online Sports Complex Booking System Project Online Sports Complex Booking System 1.0
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/categories/view_category.php?id=.
network
low complexity
online-sports-complex-booking-system-project CWE-89
critical
9.8
2022-05-12 CVE-2022-29992 SQL Injection vulnerability in Online Sports Complex Booking System Project Online Sports Complex Booking System 1.0
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/categories/manage_category.php?id=.
network
low complexity
online-sports-complex-booking-system-project CWE-89
critical
9.8
2022-05-12 CVE-2022-29993 SQL Injection vulnerability in Online Sports Complex Booking System Project Online Sports Complex Booking System 1.0
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/bookings/view_booking.php?id=.
network
low complexity
online-sports-complex-booking-system-project CWE-89
critical
9.8
2022-05-12 CVE-2022-29994 SQL Injection vulnerability in Online Sports Complex Booking System Project Online Sports Complex Booking System 1.0
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=facilities/manage_facility&id=.
network
low complexity
online-sports-complex-booking-system-project CWE-89
critical
9.8
2022-05-12 CVE-2022-29995 SQL Injection vulnerability in Online Sports Complex Booking System Project Online Sports Complex Booking System 1.0
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=clients/manage_client&id=.
network
low complexity
online-sports-complex-booking-system-project CWE-89
critical
9.8
2022-05-11 CVE-2022-30449 SQL Injection vulnerability in Hospital Management System Project Hospital Management System 1.0
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in room.php.
network
low complexity
hospital-management-system-project CWE-89
critical
9.8
2022-05-11 CVE-2022-30451 SQL Injection vulnerability in Waimairencms Project Waimairencms 9.1
An authenticated user could execute code via a SQLi vulnerability in waimairenCMS before version 9.1.
network
low complexity
waimairencms-project CWE-89
8.8